Legal
Privacy Policy
Last updated: 17 July 2026
This policy explains what data TEBOT — the Discord bot, the dashboard at tebot.app, the docs and the status page (together, the "Service") — collects, why, how long it is kept, and the choices you have. The Service is operated by the developer of TEBOT ("we", "us"), based in the United Kingdom. You can reach us at support@tebot.app.
1. Data we collect
Account data (dashboard sign-in)
You sign in with Discord OAuth. Discord shares with us your Discord user ID, username and avatar, and the list of servers you belong to, so we can show you the servers you can manage. Your server list is fetched from Discord when needed and is not kept in our database. A signed session cookie stores your login (including the Discord access token that lets us fetch your server list) in your browser.
Server configuration and content
When you configure TEBOT for a server, we store that configuration: module settings, channel and role IDs, automod filter settings and banned word lists, custom commands and autoresponders, welcome/leave messages, scheduled message text, embed designs, reaction role setups, giveaway and poll settings, stat channel templates, and patch note subscriptions. This content is authored by server staff and is stored so the bot can act on it.
Moderation and activity records
To make its features work, TEBOT stores per-server records that reference Discord user IDs:
- Warnings — the warned user's ID, the moderator's ID, the reason given, and the time;
- Moderation logs — the action taken (ban, kick, mute, automod action and similar), the user and moderator IDs, any reason and duration, and limited details of the triggering event;
- Leveling — each member's XP total, level, and time of last counted message per server;
- Tickets — who opened and claimed a ticket, its subject, status and timestamps (ticket conversations live in Discord channels, not our database);
- Premium status — the server's subscription plan and its expiry.
Message content
The bot processes messages in servers where it is installed in order to run automod, leveling and commands. This processing happens in memory: we do not keep a store of your server's chat messages, and the bot cannot see private servers it isn't in or anyone's direct messages.
Technical data and cookies
Our web server keeps short-lived standard access logs (IP address, user agent, requested URL) for security and debugging. The site uses only essential cookies: the session cookie described above and a cookie remembering your language choice. We run no advertising and no third-party analytics.
2. What we don't collect
- Your Discord password — sign-in happens on Discord's site; we never see it.
- Your email address — our Discord OAuth scopes don't request it.
- Your direct messages, or messages in servers TEBOT isn't in.
- A stored history of your server's chat messages.
- Advertising identifiers, tracking pixels or analytics profiles.
3. How we use data
We use the data above solely to operate the Service: authenticating you, showing you the right servers, running the modules you enable, enforcing Premium entitlements, keeping the Service secure and debugging problems. We do not sell personal data, and we do not use it for advertising.
4. Legal bases
Where UK/EU data protection law applies, we process data because it is necessary to provide the Service you asked for (performance of a contract), and on the basis of our legitimate interests in securing and improving the Service. Server staff are responsible for their community's use of moderation features in line with their own obligations.
5. Who we share data with
- Discord — the Service is built on Discord's platform and exchanges data with Discord's API to function; Discord's own privacy policy applies to your use of Discord.
- Hosting — the Service and its database run on infrastructure provided by Oracle Cloud.
- AI providers — if server staff use the optional AI banned-word suggestion feature, the category description they type is sent to Google (Gemini) or Anthropic to generate suggestions; no member data is included.
- Flag images — the language menu loads small flag images from flagcdn.com, so your browser makes a standard image request to that CDN.
- Payments — subscription payments are processed by Stripe, which receives your payment details directly on its own checkout pages; we never see or store card numbers. Stripe's privacy policy applies to the payment itself.
- We may also disclose data where required by law.
6. International transfers
Discord and some providers above operate in the United States and elsewhere. Where data leaves the UK, transfers rely on the safeguards those providers offer, such as approved contractual clauses.
7. Retention and deletion
Server data is kept while TEBOT is in the server, so your setup keeps working. If TEBOT is removed from a server, or the server is deleted, we keep that server's configuration for up to one year so it can be restored automatically if you re-add the bot — nothing is lost if you were just reorganising, taking a break, or trying another bot. If TEBOT hasn't been re-added within that year, the server's data is deleted permanently. If you'd like a server's data deleted sooner than that, email support@tebot.app from a position that lets us verify the request (being an administrator of that server) and we'll delete it manually. Backups are kept on a rotating basis for disaster recovery and expire automatically. You can request deletion of records referencing your user ID specifically by contacting the same address.
8. Security
The Service is served over HTTPS, the database is not exposed to the internet, access to production systems is restricted to key-based authentication, and session cookies are signed and HTTP-only. No system is perfectly secure, but we take reasonable measures appropriate to the data we hold.
9. Your rights
Under UK GDPR (and similar laws), you may have rights to access, correct, delete or restrict processing of your personal data, to object to processing, and to data portability. Contact us at support@tebot.app to exercise them. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
10. Children
The Service is not directed at children below Discord's minimum age (13, or higher where local law requires). We do not knowingly collect data from anyone not permitted to use Discord; if you believe we have, contact us and we will delete it.
11. Changes to this policy
If we make material changes — for example when payments launch or a new module stores a new category of data — we will update this page and give notice on the dashboard or our Discord server. The date at the top reflects the current version.
12. Contact
Privacy questions and requests: support@tebot.app.